โ† ISMS-P Compliance Support

ISMS-P 1.2.4 ๋ณดํ˜ธ๋Œ€์ฑ… ์„ ์ • High Risk

๋ณดํ˜ธ๋Œ€์ฑ…์ด ์ ์ ˆํžˆ ์„ ์ •๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 1.2.4๋Š” ์œ„ํ—˜ ๋ถ„์„ ๊ฒฐ๊ณผ์— ๋”ฐ๋ผ ๋ณดํ˜ธ๋Œ€์ฑ…์„ ์„ ์ •ํ•˜๊ณ  ์šฐ์„ ์ˆœ์œ„์™€ ์ดํ–‰๊ณ„ํš์„ ์ˆ˜๋ฆฝํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” Security Hub ๊ถŒ๊ณ  + SSM Automation ๊ธฐ๋ฐ˜์œผ๋กœ ๋ณดํ˜ธ๋Œ€์ฑ… ์ž๋™ ๋งคํ•‘ ๋ฐ ์ดํ–‰ ์ž๋™ํ™”๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

📋

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 1.2.4 ๋ณดํ˜ธ๋Œ€์ฑ… ์„ ์ • ์š”๊ตฌ์‚ฌํ•ญ

1.2.4

๋ณดํ˜ธ๋Œ€์ฑ… ์„ ์ •

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์œ„ํ—˜ ๋ถ„์„ ๊ฒฐ๊ณผ์— ๋”ฐ๋ผ ์‹๋ณ„๋œ ์œ„ํ—˜์— ๋Œ€ํ•œ ๋ณดํ˜ธ๋Œ€์ฑ…์„ ์„ ์ •ํ•˜๊ณ , ๋ณดํ˜ธ๋Œ€์ฑ…์˜ ์šฐ์„ ์ˆœ์œ„์™€ ์ผ์ •, ๋‹ด๋‹น์ž, ์†Œ์š”์˜ˆ์‚ฐ ๋“ฑ์„ ํฌํ•จํ•œ ์ดํ–‰๊ณ„ํš์„ ์ˆ˜๋ฆฝํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

📌 ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • Security Hub Recommendations ํ™œ์šฉ
  • Severity ๊ธฐ๋ฐ˜ ์šฐ์„ ์ˆœ์œ„ ๋ถ„๋ฅ˜
  • SSM Automation ์ดํ–‰ ์ž๋™ํ™”
  • Config Rules ์ดํ–‰ ๊ฒ€์ฆ

⚠️ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ๋ณดํ˜ธ๋Œ€์ฑ… ์„ ์ • ๋ฏธ์ˆ˜ํ–‰
  • ๊ฒฐํ•จ: ์šฐ์„ ์ˆœ์œ„ ๊ฒฐ์ • ๊ธฐ์ค€ ๋ถ€์žฌ
  • ๊ถŒ๊ณ : ์ดํ–‰๊ณ„ํš ์ˆ˜๋ฆฝ ๋ฏธํก
📄 KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ ☁️ AWS SSM Automation
📰

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

๋ณดํ˜ธ๋Œ€์ฑ… ๋ฏธ์ดํ–‰์œผ๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2018.11

Marriott ํ†ตํ•ฉ ๋ณด์•ˆ ๋ฏธ์ดํ–‰

์ธ์ˆ˜ํ•œ Starwood ์‹œ์Šคํ…œ์˜ ๋ณดํ˜ธ๋Œ€์ฑ… ๋ฏธ์ดํ–‰์œผ๋กœ 4๋…„๊ฐ„ ์นจํ•ด ์ง€์†. 2014๋…„๋ถ€ํ„ฐ ์‹œ์ž‘๋œ ๊ณต๊ฒฉ์ด 2018๋…„๊นŒ์ง€ ํƒ์ง€๋˜์ง€ ์•Š์Œ. ํ†ตํ•ฉ ๋ณด์•ˆ ์ดํ–‰๊ณ„ํš ๋ถ€์žฌ๋กœ 3์–ต 3,900๋งŒ ๋ช… ๊ณ ๊ฐ ์ •๋ณด ์œ ์ถœ, ICO๋กœ๋ถ€ํ„ฐ GDPR ๋ฒŒ๊ธˆ ยฃ18.4M ๋ถ€๊ณผ.

💡 ๊ตํ›ˆ: M&A ์‹œ ํ†ตํ•ฉ ๋ณด์•ˆ ์ดํ–‰๊ณ„ํš ์ˆ˜๋ฆฝ + ๋ณดํ˜ธ๋Œ€์ฑ… ์šฐ์„ ์ˆœ์œ„ํ™” ํ•„์ˆ˜

์ถœ์ฒ˜: Washington Post ↗
2019.05

First American ์ทจ์•ฝ์  ๋ฐฉ์น˜

๋ฐœ๊ฒฌ๋œ ์ทจ์•ฝ์ ์— ๋Œ€ํ•œ ๋ณดํ˜ธ๋Œ€์ฑ… ๋ฏธ์ดํ–‰์œผ๋กœ 8์–ต 8,500๋งŒ ๊ฑด ๋ฌธ์„œ ๋…ธ์ถœ. IDOR ์ทจ์•ฝ์ ์ด 16๋…„๊ฐ„ ๋ฐฉ์น˜๋˜์–ด ์€ํ–‰ ๊ณ„์ขŒ, SSN, ๋ชจ๊ธฐ์ง€ ๊ธฐ๋ก ๋“ฑ ๋ฏผ๊ฐ ๊ธˆ์œต ๋ฌธ์„œ๊ฐ€ URL ์กฐ์ž‘๋งŒ์œผ๋กœ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ ์ƒํƒœ๋กœ ๋…ธ์ถœ.

💡 ๊ตํ›ˆ: Severity ๊ธฐ๋ฐ˜ ์šฐ์„ ์ˆœ์œ„ ๊ฒฐ์ • + ์ทจ์•ฝ์  ์ฆ‰์‹œ ์ดํ–‰ ์ฒด๊ณ„ ํ•„์ˆ˜

์ถœ์ฒ˜: KrebsOnSecurity ↗

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

๋ณดํ˜ธ๋Œ€์ฑ… ์ดํ–‰ ์ฒด๊ณ„๊ฐ€ ๋ฏธ๊ตฌ์ถ•๋œ ์ƒํ™ฉ

❌ ์œ„ํ—˜ ์ƒํƒœ

  • ๋Œ€์ฑ… ์„ ์ •: ๋ฏธ์ˆ˜ํ–‰
  • ์šฐ์„ ์ˆœ์œ„: ๋ฏธ๊ฒฐ์ •
  • ์ดํ–‰๊ณ„ํš: ๋ฏธ์ˆ˜๋ฆฝ
  • ๋‹ด๋‹น์ž: ๋ฏธ๋ฐฐ์ •
  • ์ดํ–‰ ํ™•์ธ: ๋ฏธ๊ฒ€์ฆ

✅ ๊ถŒ์žฅ ์ƒํƒœ

  • ๋Œ€์ฑ… ์„ ์ •: Security Hub Recommendations
  • ์šฐ์„ ์ˆœ์œ„: Severity ๊ธฐ๋ฐ˜ ๋ถ„๋ฅ˜
  • ์ดํ–‰๊ณ„ํš: SSM Automation Runbooks
  • ๋‹ด๋‹น์ž: Owner ํƒœ๊ทธ + ์ž๋™ ์•Œ๋ฆผ
  • ์ดํ–‰ ํ™•์ธ: Config Rules Compliance
🚨

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: ๋ณดํ˜ธ๋Œ€์ฑ… ์ดํ–‰ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•

Security Hub์˜ ๊ถŒ๊ณ ์‚ฌํ•ญ์ด ๊ฒ€ํ† ๋˜์ง€ ์•Š๊ณ , SSM Automation์ด ๋ฏธ์„ค์ •๋˜์–ด ๋ฐœ๊ฒฌ๋œ ์œ„ํ—˜์— ๋Œ€ํ•œ ๋ณดํ˜ธ๋Œ€์ฑ…์ด ์ˆ˜๋™์œผ๋กœ๋งŒ ์ดํ–‰๋˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ดํ–‰ ๋ˆ„๋ฝ ๋ฐ ์ง€์—ฐ ์œ„ํ—˜์ด ๋†’์Šต๋‹ˆ๋‹ค.

ํ˜„์žฌ ์ƒํƒœ - ๋ณดํ˜ธ๋Œ€์ฑ… ์ดํ–‰ ์ฒด๊ณ„ ๋ถ€์žฌ
# Terraform (๋ฌธ์ œ)
# ๋ณดํ˜ธ๋Œ€์ฑ… ์ดํ–‰ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•

# Security Hub Insights ๋ฏธ์„ค์ •
# resource "aws_securityhub_insight" ๋ฏธ์กด์žฌ

# SSM Automation ๋ฏธ์„ค์ •
# resource "aws_ssm_document" ๋ฏธ์กด์žฌ

# Config Remediation ๋ฏธ์„ค์ •
# resource "aws_config_remediation_configuration" ๋ฏธ์กด์žฌ

# ์šฐ์„ ์ˆœ์œ„๋ณ„ ์•Œ๋ฆผ ๋ฏธ์„ค์ •
# resource "aws_cloudwatch_event_rule" ๋ฏธ์กด์žฌ

ISMS-P 1.2.4 ์œ„๋ฐ˜ ์‚ฌํ•ญ

๋Œ€์ฑ… ๋ฏธ์„ ์ •: ๊ถŒ๊ณ ์‚ฌํ•ญ ๋ฏธ๊ฒ€ํ† 

์šฐ์„ ์ˆœ์œ„ ๋ฏธ๊ฒฐ์ •: ๋ถ„๋ฅ˜ ์ฒด๊ณ„ ์—†์Œ

์ดํ–‰๊ณ„ํš ๋ฏธ์ˆ˜๋ฆฝ: Automation ์—†์Œ

์ดํ–‰ ๋ฏธํ™•์ธ: Compliance ๊ฒ€์ฆ ์—†์Œ

🔍

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

๋ณดํ˜ธ๋Œ€์ฑ… ์ดํ–‰ ์ฒด๊ณ„ ํƒ์ง€ ๋กœ์ง

ํƒ์ง€ ๋Œ€์ƒ ์กฐ๊ฑด ๊ฒฐ๊ณผ
Security Hub Insights aws_securityhub_insight ๋ฏธ์กด์žฌ High - ๋Œ€์ฑ… ๋ถ„๋ฅ˜ ๋ถˆ๊ฐ€
SSM Automation aws_ssm_document (Automation) ๋ฏธ์กด์žฌ High - ์ž๋™ ์ดํ–‰ ๋ถˆ๊ฐ€
Config Remediation aws_config_remediation_configuration ๋ฏธ์กด์žฌ High - ์—ฐ๋™ ์ดํ–‰ ๋ถˆ๊ฐ€
์šฐ์„ ์ˆœ์œ„ ์•Œ๋ฆผ EventBridge + SNS ๋ฏธ์„ค์ • Medium - ๋‹ด๋‹น์ž ํ†ต๋ณด ๋ถˆ๊ฐ€
🔔

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ดํ–‰ ํ˜„ํ™ฉ ์ถ”์ 

๋ณดํ˜ธ๋Œ€์ฑ… ์ดํ–‰ ํ˜„ํ™ฉ ๋Œ€์‘ ๋กœ์ง

ํƒ์ง€ ์‹œ๋‚˜๋ฆฌ์˜ค ์กฐ๊ฑด ๊ฒฐ๊ณผ
๋ฏธ์ดํ–‰ ๋Œ€์ฑ… 14์ผ+ ๋ฏธ์กฐ์น˜ High - ์—์Šค์ปฌ๋ ˆ์ด์…˜
์šฐ์„ ์ˆœ์œ„ ๋ณ€๊ฒฝ Severity ์ƒ์Šน High - ์šฐ์„ ์ˆœ์œ„ ์žฌ์กฐ์ •
์ƒˆ ๊ถŒ๊ณ ์‚ฌํ•ญ ์‹ ๊ทœ Recommendation ๋ฐœ์ƒ Medium - ๋Œ€์ฑ… ๊ฒ€ํ†  ํ•„์š”
๋Œ€์ฑ… ์™„๋ฃŒ Config Compliance = PASSED Info - ์ดํ–‰ ์™„๋ฃŒ ๊ธฐ๋ก

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

Finding ID ๊ถŒ๊ณ  ๋ณดํ˜ธ๋Œ€์ฑ… ๋‹ด๋‹น Owner ์ดํ–‰ ๊ฐ€์ด๋“œ

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

๊ถŒ์žฅ ์„ค์ • (Terraform)
protection-measures.tf
# 1. Security Hub Custom Insights (๋ณดํ˜ธ๋Œ€์ฑ… ๋ถ„๋ฅ˜)
resource "aws_securityhub_insight" "critical_findings" {
  name               = "critical-unresolved-findings"
  group_by_attribute = "ResourceId"

  filters {
    severity_label {
      comparison = "EQUALS"
      value      = "CRITICAL"
    }
    workflow_status {
      comparison = "EQUALS"
      value      = "NEW"
    }
  }
}

# 2. SSM Automation (์ž๋™ ์ดํ–‰)
resource "aws_ssm_document" "remediate_public_s3" {
  name            = "RemediatePublicS3Bucket"
  document_type   = "Automation"
  document_format = "YAML"
  content         = file("automation-docs/remediate-s3.yaml")
}

# 3. Config Remediation (์ž๋™ ์—ฐ๋™)
resource "aws_config_remediation_configuration" "s3_public" {
  config_rule_name = aws_config_config_rule.s3_public_read.name
  target_type      = "SSM_DOCUMENT"
  target_id        = aws_ssm_document.remediate_public_s3.name
  automatic        = true
}

# 4. ์šฐ์„ ์ˆœ์œ„๋ณ„ ์•Œ๋ฆผ (๋‹ด๋‹น์ž ๋ฐฐ์ •)
resource "aws_cloudwatch_event_rule" "critical_to_oncall" {
  name = "critical-findings-to-oncall"

  event_pattern = jsonencode({
    source      = ["aws.securityhub"]
    detail-type = ["Security Hub Findings - Imported"]
    detail = {
      findings = { Severity = { Label = ["CRITICAL"] } }
    }
  })
}
💡

Security Hub Insights

๋ณดํ˜ธ๋Œ€์ฑ… ๋ถ„๋ฅ˜

SSM Automation

์ž๋™ ์ดํ–‰ Runbooks

🔗

Config Remediation

์ž๋™ ์—ฐ๋™ ์ดํ–‰

🔔

์šฐ์„ ์ˆœ์œ„ ์•Œ๋ฆผ

Severity๋ณ„ ๋‹ด๋‹น์ž ํ†ต๋ณด

📊

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

📋 ์ง„๋‹จ ํ•ญ๋ชฉ

  • ๋ณดํ˜ธ๋Œ€์ฑ… ์„ ์ • ํ˜„ํ™ฉ
  • ์šฐ์„ ์ˆœ์œ„ ๋ถ„๋ฅ˜ ํ˜„ํ™ฉ
  • Automation Runbook ๊ฐœ์ˆ˜
  • ์ดํ–‰ ์™„๋ฃŒ์œจ
  • ๋ฏธ์ดํ–‰ ๋Œ€์ฑ… ์ˆ˜

📅 ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

๋ฏธ์ดํ–‰ ๋Œ€์ฑ… ์•Œ๋ฆผ

์ฃผ๊ฐ„

์ดํ–‰ ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

📤 ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

Findings ์กด์žฌ ์—ฌ๋ถ€๋งŒ ํ™•์ธ

  • ๋ณดํ˜ธ๋Œ€์ฑ… ๋งคํ•‘ ๋ฏธ๊ฒ€์ฆ
  • SSM Automation ๋ฏธํ™•์ธ
  • Config Remediation ๋ฏธ๊ฒ€์‚ฌ
  • ์ดํ–‰ ํ˜„ํ™ฉ ๋ฏธ์ถ”์ 

ํ•œ๊ณ„: ISMS-P ๊ด€์ ์˜ ๋ณดํ˜ธ๋Œ€์ฑ… ์ดํ–‰ ์ฒด๊ณ„ ์ „์ฒด๋ฅผ ์ ๊ฒ€ํ•˜์ง€ ์•Š์Œ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • ์„ ์ •: Security Hub ๊ถŒ๊ณ  ๋งคํ•‘ ๊ฒ€์ฆ
  • ์šฐ์„ ์ˆœ์œ„: Severity ๊ธฐ๋ฐ˜ ๋ถ„๋ฅ˜ ํ™•์ธ
  • ์ดํ–‰: SSM Automation ์—ฐ๋™ ๊ฒ€์ฆ
  • ์ฆ์ : ์ดํ–‰ ํ˜„ํ™ฉ ๋ฆฌํฌํŠธ ์ž๋™ํ™”

์ฐจ๋ณ„์ : ์ธ์ฆ ๊ธฐ์ค€ ๊ด€์ ์—์„œ ์„ ์ • → ์ดํ–‰ → ๊ฒ€์ฆ ์ „ ๊ณผ์ • ์ž๋™ํ™”

โ† ISMS-P Compliance Support๋กœ ๋Œ์•„๊ฐ€๊ธฐ